Cybercriminals Abusing Teams Leading to Ransomware Deployment

Red | Attack Report
Download PDF

Ransomware gangs are increasingly using sophisticated tactics to infiltrate corporate networks, combining email bombing with impersonation schemes on Microsoft Teams. Threat actors identified as STAC5143 and STAC5777 overwhelm employees with thousands of spam emails in a short time, creating confusion and urgency, and then pose as tech support through Teams calls, exploiting default settings that allow external users to initiate chats and meetings. By masquerading as IT staff, they trick employees into granting remote access to their machines, using legitimate Microsoft tools to install malware, steal sensitive data, and deploy ransomware.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox